![]() |
|
Alles rund um Windows: Viren befall ? HijackThius (fehler?)Windows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
![]() |
|
![]() | #1 | |
![]() ![]() | ![]() Problem: Viren befall ? HijackThius (fehler?) Hallo Slimix Zitat:
Der einzige Support den es hier für dich gibt ist http://www.trojaner-board.de/51262-a...sicherung.html Gruß Acid
__________________ Kein Support per PM Das befolgen der Tips und Anleitungen geschieht auf eigene Gefahr. |
![]() | #2 | |
![]() ![]() | ![]() Viren befall ? HijackThius (fehler?) Anleitung / HilfeZitat:
Ich habe von den Programmen keins genutzt! Ich hab mir die Testversion von Norton gezogen. Von den Programmen wusste ich nichts! mfg Neuaufsetzen: Gibt's da keine andere Möglichkeit? |
![]() | #3 |
![]() ![]() | ![]() Viren befall ? HijackThius (fehler?) Details Naja ein Norton crack und dann auch noch Norton in Benutzung, da liegt der Verdacht nahe. Aber ich glaube dir jetzt mal.
__________________![]() Deinstalliere als erstes einmal das Norton, zwei aktive Scanner belasten eher das System als daß sie nützen. Benutze dafür Download and run the Norton Removal Tool Dann lösche den ganzen Programm-Schrott den dein Kumpel dir da geschickt hat. Führe nichts davon aus!!!! Nun zur Bereinigung. ![]() Schritt 1: Windows-Explorer öffnen (Windows-Taste + E) und unter => Organisieren => Ordner- und Suchoptionen => im Reiter "Ansicht" * Dateien und Ordner: Erweiterungen bei bekannten Dateitypen ausblenden deaktivieren * Dateien und Ordner: Geschützte Systemdateien ausblenden (empfohlen) deaktivieren * Versteckte Dateien und Ordner: alle Dateien und Ordner anzeigen aktivieren Schritt 2: Lade dir den CCleaner runter und reinige Damit dein System. Schritt 3: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop * Doppelklick auf die OTL.exe * Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen * Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output * Unter Extra Registry, wähle bitte Use SafeList * Klicke nun auf Run Scan links oben * Wenn der Scan beendet wurde werden 2 Logfiles erstellt * Poste die Logfiles hier in den Thread. http://filepony.de/download-otl/ Schritt 4: Gmer-Scan Bevor mit GMER gescant werden kann müssen erst einige Dinge erledigt werden: Alle Scanner gegen Viren, Spyware und sonstiges müssen deaktiviert werden Alle Netzwerk- und Internetverbindungen trennen (auch WLAN) Beim Scan nichts am Rechner machen Nach dem Scan den Rechner neustarten Der GMER Scan: * GMER auf den Desktop herunter laden. * Gmer ist geeignet für => NT/W2K/XP/VISTA. * Alle geöffneten Programme schließen (auch den Browser) Hintergrundprogramme nach Möglichkeit beenden * Gmer.exe starten * Vista-User müssen das Programm als Administrator starten * Den Scan mit "Scan" starten. Nichts am Rechner machen während der Scan läuft. * Wenn der Scan fertig ist auf "Copy" klicken um das Log in die Zwischenablage zu kopieren. Mit "Ok" wird GMER beendet. * Das Log entweder direkt als Antwort posten oder als Textdatei auf den Desktop speichern falls erst der Neustart durchgeführt wird. Falls sich ein Fenster mit folgender Warnung öffnet: WARNING !!! GMER has found system modification, which might have been caused by ROOTKIT activity. Do you want to fully scan your system ? Unbedingt auf "No" klicken. Alle Scanner unbedingt einschalten bevor eine Internetverbindung hergestellt wird! Alle anfallenden logs entweder in code tags posten (# button) oder als Anhang an deine Antwort. Gruß Acid
__________________ |
![]() | #4 |
![]() ![]() | ![]() Lösung: Viren befall ? HijackThius (fehler?) Danke dir. Log: 1 Code:
ATTFilter OTL Extras logfile created on: 19.11.2009 21:53:46 - Run 1 OTL by OldTimer - Version 3.1.6.0 Folder = C:\Users\Privat\Desktop Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,94 Gb Available Physical Memory | 96,80% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 92,21 Gb Total Space | 28,22 Gb Free Space | 30,61% Space Free | Partition Type: NTFS Drive D: | 131,89 Gb Total Space | 32,62 Gb Free Space | 24,73% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PRIVAT-PC Current User Name: Privat Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1 .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found chm.file [open] -- "%SystemRoot%\hh.exe" %1 File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "AutoUpdateDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = Reg Error: Unknown registry data type -- File not found "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17 "{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Alarmstufe Rot 3 "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{99A37AC7-E724-4621-B167-500B5A52B69C}" = LastChaosGER "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{D75814C1-5AA5-4198-BFF6-093A226D9F0D}" = O&O Defrag Professional "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "BitTorrent" = BitTorrent "CCleaner" = CCleaner "Cheat Engine 5.5_is1" = Cheat Engine 5.5 "HDMI" = Intel(R) Graphics Media Accelerator Driver "HijackThis" = HijackThis 2.0.2 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5) "Spyware Doctor" = Spyware Doctor 6.1 "Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2 "TVWiz" = Intel(R) TV Wizard "Virtual Audio Cable 4.8" = Virtual Audio Cable 4.8 "VLC media player" = VLC media player 1.0.3 "Winamp" = Winamp "WinRAR archiver" = WinRAR ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 14.11.2009 17:54:19 | Computer Name = Privat-PC | Source = VSS | ID = 8194 Description = Error - 15.11.2009 18:10:19 | Computer Name = Privat-PC | Source = System Restore | ID = 8193 Description = Error - 15.11.2009 18:30:51 | Computer Name = Privat-PC | Source = VSS | ID = 8194 Description = Error - 15.11.2009 19:41:27 | Computer Name = Privat-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: Last-Chaos Cash Hack.exe, Version: 35.11.0.12, Zeitstempel: 0x4780eaf3 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0xc4c Startzeit der fehlerhaften Anwendung: 0x01ca664d24d64a48 Pfad der fehlerhaften Anwendung: C:\Users\Privat\AppData\Local\Temp\Rar$EX00.702\Last-Chaos Cash Hack.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 63e9196c-d240-11de-a303-00238b56d11f Error - 15.11.2009 19:42:06 | Computer Name = Privat-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: Last-Chaos Cash Hack.exe, Version: 35.11.0.12, Zeitstempel: 0x4780eaf3 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0xd88 Startzeit der fehlerhaften Anwendung: 0x01ca664d3ae6227a Pfad der fehlerhaften Anwendung: C:\Users\Privat\Desktop\Last-Chaos Cash Hack.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 7b6861bb-d240-11de-a303-00238b56d11f Error - 16.11.2009 16:12:31 | Computer Name = Privat-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: Last-Chaos Cash Hack.exe, Version: 35.11.0.12, Zeitstempel: 0x4780eaf3 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x1488 Startzeit der fehlerhaften Anwendung: 0x01ca66f91e915a93 Pfad der fehlerhaften Anwendung: C:\Users\Privat\Desktop\Neuer Ordner\Last-Chaos Cash Hack.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 5e270795-d2ec-11de-95e1-00238b56d11f Error - 16.11.2009 16:12:57 | Computer Name = Privat-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: Last-Chaos Cash Hack.exe, Version: 35.11.0.12, Zeitstempel: 0x4780eaf3 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x480 Startzeit der fehlerhaften Anwendung: 0x01ca66f92f7f4018 Pfad der fehlerhaften Anwendung: C:\Users\Privat\Desktop\Neuer Ordner\Last-Chaos Cash Hack.exe Pfad des fehlerhaften Moduls: unknown Berichtskennung: 6e0a7e14-d2ec-11de-95e1-00238b56d11f Error - 16.11.2009 16:49:14 | Computer Name = Privat-PC | Source = Lavasoft Ad-Aware Service | ID = 0 Description = Error - 16.11.2009 17:47:26 | Computer Name = Privat-PC | Source = VSS | ID = 8194 Description = Error - 19.11.2009 15:16:36 | Computer Name = Privat-PC | Source = Application Hang | ID = 1002 Description = Programm Nksp.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a44 Startzeit: 01ca694cb9433482 Endzeit: 32 Anwendungspfad: C:\GAMIGO\LastChaosGER\Bin\Nksp.exe Berichts-ID: 0aeb4e24-d540-11de-a9d5-00238b56d11f [ System Events ] Error - 18.11.2009 03:19:30 | Computer Name = Privat-PC | Source = DCOM | ID = 10005 Description = Error - 18.11.2009 03:19:29 | Computer Name = Privat-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Network List Service" ist vom Dienst "Network Location Awareness" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 18.11.2009 03:19:29 | Computer Name = Privat-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Network List Service" ist vom Dienst "Network Location Awareness" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 18.11.2009 03:19:30 | Computer Name = Privat-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Network List Service" ist vom Dienst "Network Location Awareness" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 18.11.2009 03:19:30 | Computer Name = Privat-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Network List Service" ist vom Dienst "Network Location Awareness" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 18.11.2009 03:19:30 | Computer Name = Privat-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Network List Service" ist vom Dienst "Network Location Awareness" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 18.11.2009 03:19:30 | Computer Name = Privat-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Network List Service" ist vom Dienst "Network Location Awareness" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 18.11.2009 03:19:30 | Computer Name = Privat-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Network List Service" ist vom Dienst "Network Location Awareness" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 18.11.2009 03:19:30 | Computer Name = Privat-PC | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Network List Service" ist vom Dienst "Network Location Awareness" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 18.11.2009 08:22:57 | Computer Name = Privat-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?18.?11.?2009 um 10:40:48 unerwartet heruntergefahren. < End of report > |
![]() | #5 |
![]() ![]() | ![]() Wie Viren befall ? HijackThius (fehler?) Log 2/1 Code:
ATTFilter OTL logfile created on: 19.11.2009 21:53:46 - Run 1 OTL by OldTimer - Version 3.1.6.0 Folder = C:\Users\Privat\Desktop Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,94 Gb Available Physical Memory | 96,80% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 92,21 Gb Total Space | 28,22 Gb Free Space | 30,61% Space Free | Partition Type: NTFS Drive D: | 131,89 Gb Total Space | 32,62 Gb Free Space | 24,73% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PRIVAT-PC Current User Name: Privat Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Users\Privat\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) PRC - C:\Program Files\OO Software\Defrag\oodag.exe (O&O Software GmbH) PRC - C:\Program Files\OO Software\Defrag\oodtray.exe (O&O Software GmbH) PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation) PRC - C:\Windows\System32\igfxtray.exe (Intel Corporation) PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation) PRC - C:\Windows\System32\igfxsrvc.exe (Intel Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools) PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools) PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Windows\System32\WUDFHost.exe (Microsoft Corporation) PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Windows\System32\wbem\WmiPrvSE.exe (Microsoft Corporation) PRC - \\?\C:\Windows\System32\wbem\WMIADAP.EXE () PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Windows\System32\sppsvc.exe (Microsoft Corporation) PRC - C:\Program Files\Winamp\winampa.exe () PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools) PRC - C:\Program Files\Teamspeak2_RC2\TeamSpeak.exe (Dominating Bytes Design) ========== Modules (SafeList) ========== MOD - C:\Users\Privat\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation) MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation) MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation) MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation) MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation) MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation) MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation) MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation) MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation) MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation) MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation) MOD - C:\Program Files\Spyware Doctor\pctgmhk.dll (PC Tools) MOD - C:\Program Files\Spyware Doctor\klg.dat (PC Tools) MOD - C:\Program Files\Spyware Doctor\smum32.dll (PC Tools) ========== Win32 Services (SafeList) ========== SRV - (O&O Defrag) -- C:\Program Files\OO Software\Defrag\oodag.exe (O&O Software GmbH) SRV - (sdCoreService) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (WwanSvc) -- C:\Windows\System32\wwansvc.dll (Microsoft Corporation) SRV - (WbioSrvc) -- C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation) SRV - (Power) -- C:\Windows\System32\umpo.dll (Microsoft Corporation) SRV - (Themes) -- C:\Windows\System32\themeservice.dll (Microsoft Corporation) SRV - (sppuinotify) -- C:\Windows\System32\sppuinotify.dll (Microsoft Corporation) SRV - (RpcEptMapper) -- C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation) SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation) SRV - (PNRPsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation) SRV - (p2pimsvc) -- C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation) SRV - (HomeGroupProvider) -- C:\Windows\System32\provsvc.dll (Microsoft Corporation) SRV - (PNRPAutoReg) -- C:\Windows\System32\pnrpauto.dll (Microsoft Corporation) SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (HomeGroupListener) -- C:\Windows\System32\ListSvc.dll (Microsoft Corporation) SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation) SRV - (Dhcp) -- C:\Windows\System32\dhcpcore.dll (Microsoft Corporation) SRV - (defragsvc) -- C:\Windows\System32\defragsvc.dll (Microsoft Corporation) SRV - (BDESVC) -- C:\Windows\System32\bdesvc.dll (Microsoft Corporation) SRV - (AxInstSV) -- C:\Windows\System32\AxInstSv.dll (Microsoft Corporation) SRV - (AppIDSvc) -- C:\Windows\System32\appidsvc.dll (Microsoft Corporation) SRV - (WMPNetworkSvc) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) SRV - (sppsvc) -- C:\Windows\System32\sppsvc.exe (Microsoft Corporation) SRV - (ehRecvr) -- C:\Windows\ehome\ehrecvr.exe (Microsoft Corporation) SRV - (ehSched) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (FontCache3.0.0.0) -- C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (NetTcpPortSharing) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (idsvc) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (sdAuxService) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools) ========== Driver Services (SafeList) ========== DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys () DRV - (RTL8187B) -- C:\Windows\System32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation ) DRV - (RTL8167) -- C:\Windows\System32\drivers\Rt86win7.sys (Realtek ) DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation) DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH) DRV - (cmdide) -- C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.) DRV - (adpahci) -- C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.) DRV - (adp94xx) -- C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.) DRV - (amdsbs) -- C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.) DRV - (adpu320) -- C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.) DRV - (arcsas) -- C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.) DRV - (amdsata) -- C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices) DRV - (arc) -- C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.) DRV - (amdxata) -- C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices) DRV - (aliide) -- C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.) DRV - (nvstor) -- C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation) DRV - (nvraid) -- C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation) DRV - (nfrd960) -- C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation) DRV - (LSI_SAS) -- C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation) DRV - (iaStorV) -- C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation) DRV - (MegaSR) -- C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.) DRV - (KSecPkg) -- C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation) DRV - (LSI_SCSI) -- C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation) DRV - (LSI_FC) -- C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation) DRV - (LSI_SAS2) -- C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation) DRV - (iirsp) -- C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (megasas) -- C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation) DRV - (hwpolicy) -- C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation) DRV - (elxstor) -- C:\Windows\system32\DRIVERS\elxstor.sys (Emulex) DRV - (aic78xx) -- C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.) DRV - (HpSAMD) -- C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company) DRV - (FsDepends) -- C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation) DRV - (vsmraid) -- C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation) DRV - (vhdmp) -- C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation) DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation) DRV - (vdrvroot) -- C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation) DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation) DRV - (WIMMount) -- C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation) DRV - (viaide) -- C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.) DRV - (ql2300) -- C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation) DRV - (rdyboost) -- C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation) DRV - (ql40xx) -- C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation) DRV - (SiSRaid4) -- C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems) DRV - (pcw) -- C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation) DRV - (SiSRaid2) -- C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.) DRV - (stexstor) -- C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology) DRV - (CNG) -- C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation) DRV - (Brserid) -- C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.) DRV - (rdpbus) -- C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation) DRV - (RDPREFMP) -- C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation) DRV - (RasAgileVpn) -- C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation) DRV - (WfpLwf) -- C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation) DRV - (NdisCap) -- C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation) DRV - (vwififlt) -- C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation) DRV - (vwifibus) -- C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation) DRV - (1394ohci) -- C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation) DRV - (UmPass) -- C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation) DRV - (mshidkmdf) -- C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation) DRV - (MTConfig) -- C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation) DRV - (CompositeBus) -- C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation) DRV - (AppID) -- C:\Windows\system32\drivers\appid.sys (Microsoft Corporation) DRV - (scfilter) -- C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation) DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation) DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation) DRV - (discache) -- C:\Windows\System32\drivers\discache.sys (Microsoft Corporation) DRV - (HidBatt) -- C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation) DRV - (AcpiPmi) -- C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation) DRV - (AmdPPM) -- C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation) DRV - (hcw85cir) -- C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV - (BrUsbMdm) -- C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.) DRV - (BrUsbSer) -- C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.) DRV - (BrSerWdm) -- C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.) DRV - (BrFiltLo) -- C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.) DRV - (BrFiltUp) -- C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.) DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation) DRV - (ebdrv) -- C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation) DRV - (b06bdrv) -- C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation) DRV - (secdrv) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH) DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH) DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (EuMusDesignVirtualAudioCableWdm) -- C:\Windows\System32\drivers\vrtaucbl.sys (Eugene V. Muzychenko) DRV - (USBPNPA) -- C:\Windows\System32\drivers\CM108.sys (C-Media Inc) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4C 46 32 48 95 65 CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.5 FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.11.18 13:33:49 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009.11.18 13:33:46 | 00,000,000 | ---D | M] [2009.11.18 13:34:00 | 00,000,000 | ---D | M] -- C:\Users\Privat\AppData\Roaming\mozilla\Extensions [2009.11.18 13:34:00 | 00,000,000 | ---D | M] -- C:\Users\Privat\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009.11.19 21:23:35 | 00,000,000 | ---D | M] -- C:\Users\Privat\AppData\Roaming\mozilla\Firefox\Profiles\r7240r0p.default\extensions [2009.11.18 13:44:32 | 00,000,000 | ---D | M] -- C:\Users\Privat\AppData\Roaming\mozilla\Firefox\Profiles\r7240r0p.default\extensions\de-DE@dictionaries.addons.mozilla.org [2009.11.18 13:33:46 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009.11.18 13:33:46 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009.11.05 23:16:40 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2009.11.03 04:27:25 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009.11.03 04:27:25 | 00,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009.09.25 17:41:48 | 01,044,480 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\libdivx.dll [2009.11.05 23:16:33 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll [2009.09.25 17:41:24 | 01,650,992 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll [2009.11.03 04:27:25 | 00,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2009.09.25 17:41:48 | 00,200,704 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\ssldivx.dll [2009.11.03 03:14:39 | 00,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml [2009.11.03 03:14:39 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml [2009.11.03 03:14:39 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009.11.03 03:14:39 | 00,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml [2009.11.03 03:14:39 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml [2009.11.03 03:14:39 | 00,000,801 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml Geändert von Slimix87 (19.11.2009 um 22:10 Uhr) |
![]() | #6 |
![]() ![]() | ![]() Wo Viren befall ? HijackThius (fehler?) Lösung! Log 2/2 Code:
ATTFilter O1 HOSTS File: (824 bytes) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools) O4 - HKLM..\Run: [OODefragTray] C:\Program Files\OO Software\Defrag\oodtray.exe (O&O Software GmbH) O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 22:42:20 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{dd9fd7cf-ce16-11de-9b11-00238b56d11f}\Shell - "" = AutoRun O33 - MountPoints2\{dd9fd7cf-ce16-11de-9b11-00238b56d11f}\Shell\AutoRun\command - "" = G:\CDautorun.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O34 - HKLM BootExecute: (OODBS) - C:\Windows\System32\OODBS.exe (O&O Software GmbH) O35 - comfile [open] -- "%1" %* File not found O35 - exefile [open] -- "%1" %* File not found ========== Files/Folders - Created Within 30 Days ========== [2009.11.19 21:44:16 | 00,529,408 | ---- | C] (OldTimer Tools) -- C:\Users\Privat\Desktop\OTL.exe [2009.11.19 20:22:40 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Local\Tific [2009.11.19 20:22:37 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\Tific [2009.11.19 00:08:44 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Local\eSupport.com [2009.11.18 23:55:25 | 00,000,000 | ---D | C] -- C:\Program Files\Lavalys [2009.11.18 13:33:56 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\Mozilla [2009.11.17 21:24:46 | 00,000,000 | ---D | C] -- C:\Program Files\DAMN NFO Viewer [2009.11.17 21:19:07 | 00,000,000 | ---D | C] -- C:\ProgramData\Norton [2009.11.17 21:19:07 | 00,000,000 | ---D | C] -- C:\ProgramData\Norton [2009.11.17 21:18:50 | 00,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller [2009.11.17 21:18:50 | 00,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller [2009.11.16 22:47:57 | 00,096,104 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2009.11.16 22:47:57 | 00,055,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2009.11.16 22:47:57 | 00,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2009.11.16 22:47:56 | 00,000,000 | ---D | C] -- C:\ProgramData\Avira [2009.11.16 22:47:56 | 00,000,000 | ---D | C] -- C:\ProgramData\Avira [2009.11.16 22:47:56 | 00,000,000 | ---D | C] -- C:\Program Files\Avira [2009.11.16 21:51:18 | 00,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE [2009.11.16 21:50:51 | 00,093,360 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys [2009.11.16 21:48:13 | 00,000,000 | ---D | C] -- C:\ProgramData\Lavasoft [2009.11.16 21:48:13 | 00,000,000 | ---D | C] -- C:\ProgramData\Lavasoft [2009.11.16 16:50:20 | 00,159,600 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys [2009.11.16 16:50:14 | 00,206,256 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys [2009.11.16 16:50:14 | 00,073,840 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys [2009.11.16 16:50:08 | 00,000,000 | ---D | C] -- C:\ProgramData\TEMP [2009.11.16 16:50:08 | 00,000,000 | ---D | C] -- C:\ProgramData\TEMP [2009.11.16 16:50:04 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools [2009.11.16 16:50:03 | 00,064,392 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys [2009.11.16 16:49:55 | 00,000,000 | ---D | C] -- C:\ProgramData\PC Tools [2009.11.16 16:49:55 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\PC Tools [2009.11.16 16:49:55 | 00,000,000 | ---D | C] -- C:\ProgramData\PC Tools [2009.11.16 16:49:55 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor [2009.11.16 14:43:46 | 00,000,000 | ---D | C] -- C:\Windows\System32\Service [2009.11.16 01:40:34 | 00,000,000 | ---D | C] -- C:\Users\Privat\Documents\Command and Conquer Generals Zero Hour Data [2009.11.15 23:53:57 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\Malwarebytes [2009.11.15 23:53:49 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2009.11.15 23:53:43 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2009.11.15 23:53:43 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2009.11.15 23:53:43 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2009.11.15 23:53:43 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009.11.15 23:46:38 | 00,000,000 | ---D | C] -- C:\Users\Privat\Documents\Command and Conquer Generals Data [2009.11.15 22:43:35 | 00,000,000 | ---D | C] -- C:\Program1 [2009.11.12 00:29:36 | 00,000,000 | ---D | C] -- C:\Users\Privat\Documents\Red Alert 3 [2009.11.11 23:59:10 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Local\Diagnostics [2009.11.10 18:02:49 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\Red Alert 3 [2009.11.10 17:40:53 | 00,000,000 | ---D | C] -- C:\Program Files\Electronic Arts [2009.11.10 17:40:50 | 03,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll [2009.11.10 17:40:50 | 01,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll [2009.11.10 17:40:50 | 00,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll [2009.11.10 17:40:49 | 03,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll [2009.11.10 17:40:49 | 01,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll [2009.11.10 17:40:49 | 00,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll [2009.11.10 17:32:46 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite [2009.11.10 17:32:06 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\DAEMON Tools Lite [2009.11.10 17:32:04 | 00,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite [2009.11.10 17:32:04 | 00,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite [2009.11.10 17:29:02 | 00,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Pro [2009.11.10 17:29:02 | 00,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Pro [2009.11.10 17:29:02 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Pro [2009.11.10 17:24:24 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\DAEMON Tools Pro [2009.11.10 13:14:35 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\BitTorrent [2009.11.10 13:14:27 | 00,000,000 | ---D | C] -- C:\Program Files\BitTorrent [2009.11.10 13:09:01 | 00,000,000 | ---D | C] -- C:\Windows\System32\oodag [2009.11.10 13:07:22 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Local\O&O [2009.11.10 13:06:48 | 00,000,000 | ---D | C] -- C:\Program Files\OO Software [2009.11.08 19:52:11 | 00,679,936 | ---- | C] (Generated by JEDI) -- C:\Windows\System32\D3DX81ab.dll [2009.11.08 19:52:10 | 00,000,000 | ---D | C] -- C:\Program Files\Cheat Engine [2009.11.07 15:09:00 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro [2009.11.06 03:43:22 | 00,000,000 | ---D | C] -- C:\Windows\Panther [2009.11.06 03:43:07 | 00,000,000 | -HSD | C] -- C:\Boot [2009.11.06 00:34:14 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Local\Microsoft Games [2009.11.05 23:59:30 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner [2009.11.05 23:27:41 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\WinRAR [2009.11.05 23:27:17 | 00,000,000 | ---D | C] -- C:\Program Files\WinRAR [2009.11.05 23:20:50 | 00,000,000 | ---D | C] -- C:\Program Files\DivX [2009.11.05 23:20:50 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DivX Shared [2009.11.05 23:19:16 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\Macromedia [2009.11.05 23:19:16 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\Adobe [2009.11.05 23:18:11 | 00,000,000 | ---D | C] -- C:\Windows\System32\Macromed [2009.11.05 23:16:39 | 00,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deploytk.dll [2009.11.05 23:16:39 | 00,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe [2009.11.05 23:16:39 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe [2009.11.05 23:16:39 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe Geändert von Slimix87 (19.11.2009 um 22:10 Uhr) |
![]() | #7 |
![]() ![]() | ![]() Viren befall ? HijackThius (fehler?) 2/3 Code:
ATTFilter [2009.11.05 23:16:31 | 00,000,000 | ---D | C] -- C:\Program Files\Java [2009.11.05 23:13:47 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\vlc [2009.11.05 23:13:11 | 00,000,000 | ---D | C] -- C:\Program Files\VideoLAN [2009.11.05 23:06:40 | 00,042,752 | ---- | C] (Eugene V. Muzychenko) -- C:\Windows\System32\drivers\vrtaucbl.sys [2009.11.05 23:06:39 | 00,000,000 | ---D | C] -- C:\Program Files\Virtual Audio Cable [2009.11.05 20:18:04 | 00,000,000 | ---D | C] -- C:\GAMIGO [2009.11.05 20:18:03 | 00,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information [2009.11.05 20:17:34 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield [2009.11.05 19:47:57 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine [2009.11.05 19:47:55 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\Winamp [2009.11.05 19:47:55 | 00,000,000 | ---D | C] -- C:\Program Files\Winamp [2009.11.05 19:38:57 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\teamspeak2 [2009.11.05 19:38:43 | 00,034,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lhacm.acm [2009.11.05 19:38:39 | 00,000,000 | ---D | C] -- C:\Program Files\Teamspeak2_RC2 [2009.11.05 19:23:50 | 00,000,000 | ---D | C] -- C:\Program Files\AVG [2009.11.05 19:23:13 | 00,000,000 | -HSD | C] -- C:\Windows\Installer [2009.11.05 19:16:21 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Local\Mozilla [2009.11.05 19:16:17 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2009.11.05 19:10:08 | 00,398,848 | ---- | C] (Intel(R) Corporation) -- C:\Windows\System32\TVWizudlg.exe [2009.11.05 19:10:00 | 00,000,000 | ---D | C] -- C:\Windows\System32\Lang [2009.11.05 19:09:59 | 00,000,000 | ---D | C] -- C:\Program Files\Intel [2009.11.05 19:07:40 | 01,002,008 | ---- | C] (Intel Corporation) -- C:\Windows\System32\igxpun.exe [2009.11.05 19:07:40 | 00,000,000 | ---D | C] -- C:\Windows\System32\x64 [2009.11.05 19:07:18 | 00,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msv1_0.dll [2009.11.05 19:06:41 | 26,768,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MRT.exe [2009.11.05 19:06:26 | 00,195,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe [2009.11.05 19:04:39 | 00,000,000 | ---D | C] -- C:\Windows\de-DE [2009.11.05 19:04:30 | 00,000,000 | ---D | C] -- C:\Windows\System32\XPSViewer [2009.11.05 19:04:30 | 00,000,000 | ---D | C] -- C:\Windows\System32\0407 [2009.11.05 19:04:29 | 00,000,000 | ---D | C] -- C:\Windows\System32\drivers\de-DE [2009.11.05 19:04:26 | 00,000,000 | ---D | C] -- C:\Windows\System32\de [2009.11.05 19:01:43 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\volsnap.sys.mui [2009.11.05 19:01:43 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\usbport.sys.mui [2009.11.05 19:01:43 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\usbhub.sys.mui [2009.11.05 19:01:43 | 00,004,096 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\de-DE\pscr.sys.mui [2009.11.05 19:01:43 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\vhdmp.sys.mui [2009.11.05 19:01:43 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\tpm.sys.mui [2009.11.05 19:01:43 | 00,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\portcls.sys.mui [2009.11.05 19:01:43 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\umbus.sys.mui [2009.11.05 19:01:43 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\serscan.sys.mui [2009.11.05 19:01:43 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\wd.sys.mui [2009.11.05 19:01:42 | 00,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pcmcia.sys.mui [2009.11.05 19:01:41 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mpio.sys.mui [2009.11.05 19:01:41 | 00,033,280 | ---- | C] (Marvell) -- C:\Windows\System32\drivers\de-DE\yk62x86.sys.mui [2009.11.05 19:01:41 | 00,025,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1y6032.sys.mui [2009.11.05 19:01:41 | 00,025,088 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1e6032.sys.mui [2009.11.05 19:01:41 | 00,022,016 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\E1G60I32.sys.mui [2009.11.05 19:01:41 | 00,013,312 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1q6032.sys.mui [2009.11.05 19:01:41 | 00,013,312 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e1k6032.sys.mui [2009.11.05 19:01:41 | 00,013,312 | ---- | C] (Broadcom Corporation) -- C:\Windows\System32\drivers\de-DE\k57nd60x.sys.mui [2009.11.05 19:01:41 | 00,013,312 | ---- | C] (Broadcom Corporation) -- C:\Windows\System32\drivers\de-DE\b57nd60x.sys.mui [2009.11.05 19:01:41 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\serial.sys.mui [2009.11.05 19:01:41 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\i8042prt.sys.mui [2009.11.05 19:01:41 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\msdsm.sys.mui [2009.11.05 19:01:41 | 00,006,144 | ---- | C] (Broadcom Corporation) -- C:\Windows\System32\drivers\de-DE\bcm4sbxp.sys.mui [2009.11.05 19:01:41 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\sermouse.sys.mui [2009.11.05 19:01:41 | 00,005,120 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\de-DE\e100b325.sys.mui [2009.11.05 19:01:41 | 00,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mouclass.sys.mui [2009.11.05 19:01:41 | 00,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\parport.sys.mui [2009.11.05 19:01:41 | 00,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ataport.sys.mui [2009.11.05 19:01:41 | 00,003,072 | ---- | C] (VIA Technologies, Inc. ) -- C:\Windows\System32\drivers\de-DE\getn62.sys.mui [2009.11.05 19:01:41 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\scsiport.sys.mui [2009.11.05 19:01:41 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\rndismpx.sys.mui [2009.11.05 19:01:41 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\rndismp6.sys.mui [2009.11.05 19:01:41 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\parvdm.sys.mui [2009.11.05 19:01:41 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mouhid.sys.mui [2009.11.05 19:01:41 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\vwifibus.sys.mui [2009.11.05 19:01:41 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\MTConfig.sys.mui [2009.11.05 19:01:41 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\amdide.sys.mui [2009.11.05 19:01:40 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bfe.dll.mui [2009.11.05 19:01:40 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\afd.sys.mui [2009.11.05 19:01:40 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\wdf01000.sys.mui [2009.11.05 19:01:40 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ws2ifsl.sys.mui [2009.11.05 19:01:40 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\usbrpm.sys.mui [2009.11.05 19:01:39 | 00,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\tcpip.sys.mui [2009.11.05 19:01:39 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\tunnel.sys.mui [2009.11.05 19:01:39 | 00,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\modem.sys.mui [2009.11.05 19:01:38 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\fvevol.sys.mui [2009.11.05 19:01:38 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\srv.sys.mui [2009.11.05 19:01:38 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\scfilter.sys.mui [2009.11.05 19:01:35 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pacer.sys.mui [2009.11.05 19:01:35 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\rdbss.sys.mui [2009.11.05 19:01:35 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\RNDISMP.sys.mui [2009.11.05 19:01:35 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\qwavedrv.sys.mui [2009.11.05 19:01:34 | 00,072,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ntfs.sys.mui [2009.11.05 19:01:34 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ndis.sys.mui [2009.11.05 19:01:34 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\nwifi.sys.mui [2009.11.05 19:01:34 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ndisuio.sys.mui [2009.11.05 19:01:34 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\partmgr.sys.mui [2009.11.05 19:01:33 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ndiscap.sys.mui [2009.11.05 19:01:33 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mountmgr.sys.mui [2009.11.05 19:01:32 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\http.sys.mui [2009.11.05 19:01:32 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\luafv.sys.mui [2009.11.05 19:01:32 | 00,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ipnat.sys.mui [2009.11.05 19:01:30 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\fltmgr.sys.mui [2009.11.05 19:01:30 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\volmgrx.sys.mui [2009.11.05 19:01:29 | 00,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\de-DE\BrSerIb.sys.mui [2009.11.05 19:01:29 | 00,010,752 | ---- | C] (Agere Systems) -- C:\Windows\System32\drivers\de-DE\ltmdmnt.sys.mui [2009.11.05 19:01:29 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pci.sys.mui [2009.11.05 19:01:29 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\IPMIDrv.sys.mui [2009.11.05 19:01:29 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\kbdclass.sys.mui [2009.11.05 19:01:29 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\wacompen.sys.mui [2009.11.05 19:01:29 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\vdrvroot.sys.mui [2009.11.05 19:01:29 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\isapnp.sys.mui [2009.11.05 19:01:29 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\hdaudbus.sys.mui [2009.11.05 19:01:29 | 00,003,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\HdAudio.sys.mui [2009.11.05 19:01:29 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\mssmbios.sys.mui [2009.11.05 19:01:29 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\hidbth.sys.mui [2009.11.05 19:01:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\VIAAGP.SYS.mui [2009.11.05 19:01:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ULIAGPKX.SYS.mui [2009.11.05 19:01:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\SISAGP.SYS.mui [2009.11.05 19:01:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\pnpmem.sys.mui [2009.11.05 19:01:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\NV_AGP.SYS.mui [2009.11.05 19:01:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\kbdhid.sys.mui [2009.11.05 19:01:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\Dot4usb.sys.mui [2009.11.05 19:01:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\AMDAGP.SYS.mui [2009.11.05 19:01:29 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\AGP440.sys.mui [2009.11.05 19:01:28 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\viac7.sys.mui [2009.11.05 19:01:28 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\processr.sys.mui [2009.11.05 19:01:28 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\intelppm.sys.mui [2009.11.05 19:01:28 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\amdppm.sys.mui [2009.11.05 19:01:28 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\amdk8.sys.mui [2009.11.05 19:01:28 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\ohci1394.sys.mui [2009.11.05 19:01:28 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\1394ohci.sys.mui [2009.11.05 19:01:28 | 00,011,776 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\de-DE\BrSerId.sys.mui [2009.11.05 19:01:28 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\acpi.sys.mui [2009.11.05 19:01:28 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\battc.sys.mui [2009.11.05 19:01:28 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bthport.sys.mui [2009.11.05 19:01:28 | 00,004,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bthpan.sys.mui [2009.11.05 19:01:28 | 00,003,584 | ---- | C] (ATI Technologies Inc.) -- C:\Windows\System32\drivers\de-DE\atikmdag.sys.mui [2009.11.05 19:01:28 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\UAGP35.SYS.mui [2009.11.05 19:01:28 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\GAGP30KX.SYS.mui [2009.11.05 19:01:28 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\BTHUSB.SYS.mui [2009.11.05 19:01:28 | 00,002,560 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\de-DE\BrParwdm.sys.mui [2009.11.05 19:01:28 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\disk.sys.mui [2009.11.05 19:01:28 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\cdrom.sys.mui [2009.11.05 19:01:28 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\de-DE\bthenum.sys.mui [2009.11.05 19:00:31 | 05,958,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll [2009.11.05 19:00:29 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2009.11.05 19:00:27 | 11,406,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmp.dll [2009.11.05 19:00:26 | 01,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll [2009.11.05 19:00:26 | 00,728,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgkrnl.sys [2009.11.05 19:00:25 | 12,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL [2009.11.05 19:00:25 | 02,613,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe [2009.11.05 19:00:25 | 00,507,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe [2009.11.05 19:00:25 | 00,442,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe [2009.11.05 19:00:25 | 00,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll [2009.11.05 19:00:25 | 00,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll [2009.11.05 19:00:25 | 00,071,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll [2009.11.05 19:00:12 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msasn1.dll [2009.11.05 18:52:31 | 00,000,000 | R--D | C] -- C:\Users\Privat\Searches [2009.11.05 18:52:19 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\Identities [2009.11.05 18:52:17 | 00,000,000 | R--D | C] -- C:\Users\Privat\Contacts [2009.11.05 18:52:07 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Local\VirtualStore [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\Templates [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\Start Menu [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\SendTo [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\Recent [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\PrintHood [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\NetHood [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\Documents\My Videos [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\Documents\My Pictures [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\Documents\My Music [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\My Documents [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\Local Settings [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\Cookies [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\Application Data [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\AppData\Local\Temporary Internet Files [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\AppData\Local\History [2009.11.05 18:52:06 | 00,000,000 | -HSD | C] -- C:\Users\Privat\AppData\Local\Application Data [2009.11.05 18:52:05 | 00,000,000 | --SD | C] -- C:\Users\Privat\AppData\Roaming\Microsoft [2009.11.05 18:52:05 | 00,000,000 | R--D | C] -- C:\Users\Privat\Videos [2009.11.05 18:52:05 | 00,000,000 | R--D | C] -- C:\Users\Privat\Saved Games [2009.11.05 18:52:05 | 00,000,000 | R--D | C] -- C:\Users\Privat\Pictures [2009.11.05 18:52:05 | 00,000,000 | R--D | C] -- C:\Users\Privat\Music [2009.11.05 18:52:05 | 00,000,000 | R--D | C] -- C:\Users\Privat\Links [2009.11.05 18:52:05 | 00,000,000 | R--D | C] -- C:\Users\Privat\Favorites [2009.11.05 18:52:05 | 00,000,000 | R--D | C] -- C:\Users\Privat\Downloads [2009.11.05 18:52:05 | 00,000,000 | R--D | C] -- C:\Users\Privat\Documents [2009.11.05 18:52:05 | 00,000,000 | R--D | C] -- C:\Users\Privat\Desktop [2009.11.05 18:52:05 | 00,000,000 | -H-D | C] -- C:\Users\Privat\AppData [2009.11.05 18:52:05 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Roaming\Media Center Programs [2009.11.05 18:52:05 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Local\Temp [2009.11.05 18:52:05 | 00,000,000 | ---D | C] -- C:\Users\Privat\AppData\Local\Microsoft [2009.11.05 18:51:53 | 00,000,000 | -HSD | C] -- C:\Recovery [2009.11.05 18:47:06 | 00,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2009.11.05 18:44:57 | 00,000,000 | ---D | C] -- C:\Windows\Prefetch [2009.11.05 18:44:12 | 00,000,000 | -HSD | C] -- C:\System Volume Information |
![]() |
Themen zu Viren befall ? HijackThius (fehler?) |
0 bytes, antivir, antivir guard, bedrohung gefunden, bho, desktop, fehler, fehler?, firefox, helper, hijack, home, internet explorer, internet security, internet security 2010, intrusion prevention, kein fund, keygen, log-files, malwarebytes' anti-malware, mozilla, nicht mehr öffnen, nt.dll, ntdll.dll, plug-in, problem, registry, scan, security, software, spyware, suchlauf, symantec, system, teamspeak, verweise, viren, virus gefunden, windows, windows xp, wuauclt.exe |